DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20, are rejected under 35 U.S.C. 103 as being unpatentable over Howlett et al., USPN 2021/0273949, in view of Lei et al., CN 113904797A, as outlined with provided translation, in further view of Dean et al., USPN 2020/0280575.
With regard to claims 1, 12 and 20, Howlett discloses a method for detecting anomalous behavior in devices within a network (0006), the method including identifying, from a first plurality of packets intercepted in a network, a subset of packets corresponding to a first device of a plurality of devices in the network (0050-0052, 0146-0151), extracting a plurality of deterministic features from the subset of packets (0148, 0139, 0146-0147), determining a deviation of the plurality of deterministic features from a deterministic profile of the first device (0148, 0068, 0107, 0147), wherein the deterministic profile includes features representing a normal behavioral pattern of the first device (0148, 0068, 0107, 0147), determining a first probability of anomalous behavior from the first device by inputting a first feature vector including device-specific traffic information generated from the subset of packets into a first device anomaly model for the first device (0146, 0036), wherein the first device anomaly model is one of a plurality of device anomaly models (0146, “one or more Artificial Intelligence models each trained on different users, devices” 0036, 0041, 0044), and wherein the first device anomaly model excludes traffic or features from any other device (the model from that specific device 0036, 0044, 0046), determining a second probability of anomalous behavior in the network by inputting the second feature vector including network-specific traffic information generated from the first plurality of packets into a network anomaly model (0147-0149), calculating a risk score associated with the first device as a function of (i) the deviation,(ii) the first probability output by the first device anomaly model (0128-0129), and (iii) the second probability output by the network anomaly model, computed contemporaneously from traffic observed in a common analysis window (0136, 0141-0149, 0128-0129), determining, using an attack classification model, an attack type of the first device, wherein the attack classification model is retrained based on analyst feedback (0141, 0061, 0063, 0122), and executing a remediation action based on the attack type to resolve anomalous behavior in the first device in response to determining that the risk score is greater than a threshold risk score (0053, 0055, 0061, 0088, 0122-0128, 0140). Howlett does not disclose that the device is one of a plurality protected by the network. Lei discloses a method for detecting anomalous behavior in devices within a network (page 3 paragraph beginning “the purpose”), similar to that of Howlett, and further discloses the device is a part of an internet of things (page 3 paragraph beginning “to achieve”), and detecting behavior of one device (page 3 paragraph beginning “further, the IOT event”). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to have the device of Howlett be one of several in an IOT, and the device specific packets be a subset of the total network packets, as taught by Lei, for the motivation of protecting each device in such as system. Howlett discloses “one or more Artificial Intelligence models each trained on different users, devices, system activities and interactions between entities in the system“ (0036), but Howlett in view of Lei does not specifically disclose that each anomaly model includes an individual model for a respective device of the plurality of devices trained using a device-specific training dataset. Dean discloses a method for detecting anomalous behavior in devices within a network using trained machine learning models (0006-0013, claim 28), similar to that of Howlett and Lei, and further discloses each anomaly model includes an individual model for a respective device of the plurality of devices trained using a device-specific training dataset (claim 28, 0012). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to have each anomaly model includes an individual model for a respective device of the plurality of devices trained using a device-specific training dataset, as taught by Dean, in the method of Howlett in view of Lei, for the motivation of protecting each device in a unified manner and to utilize anomaly models based on violation category rather than historical behavior.
With regard to claims 2 and 13, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the attack classification model is configured to classify an anomaly vector into a respective attack type (0141, 0061, 0063, 0122).
With regard to claims 3 and 14, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses intercepting, during a training phase prior to intercepting the first plurality of packets, a second plurality of packets of the network over a period of time, identifying the plurality of devices in the network based on the second plurality of packets (0035-0038, 0041-0049).
With regard to claims 4 and 15, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses for each respective device of the plurality of devices extracting deterministic features of the respective device from the second plurality of packets, generating a respective deterministic profile based on the extracted deterministic features of the respective device (0067, 0135, 0148, 0068, 0107, 0147).
With regard to claims 5 and 16, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the extracted deterministic features of the respective device include one or more of: protocols used at different layers of a transmission control protocol (TCP) or internet protocol (IP) stack (0113-0115)
With regard to claims 6 and 17, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, but do not disclose the respective deterministic profile is a hash table including hash values representing the extracted deterministic features. The examiner took official notice that it is well known in the art to store data as a hash table. Since this notice was not traversed, it is taken as admitted prior art (MPEP 2144.03). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to store the profile of Howlett in view of Lei in further view of Dean as a hash table, for the motivation of saving space and reducing computation, a stated motivations of Howlett (0106, 0146)
With regard to claims 7 and 18, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses generating, for each respective device of the plurality of devices, a device-specific training dataset including a plurality of feature vectors using the second plurality of packets, training, for each respective device of the plurality of devices, a respective device anomaly detection AI model using the device-specific training dataset, wherein the respective device anomaly detection AI model is configured to classify an input feature vector as anomalous or non-anomalous and output an associated probability (0036, 0049, 0062-0063), as does Lei (page 5 paragraph beginning “Referring to FIG 1”).
With regard to claims 8 and 19, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses generating, for the network, a network-specific training dataset including a plurality of feature vectors labelled by anomalous or non-anomalous classes using the second plurality of packets, training, for the network, the network anomaly detection AI model using the network-specific training dataset, wherein the network anomaly detection AI model is configured to classify an input feature vector as anomalous or non-anomalous and output an associated probability (0036, 0049, 0062-0063), as does Lei (page 5 paragraph beginning “Referring to FIG 1”).
With regard to claim 9, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the first feature vector includes, for the first device, one or more of: a size of each packet, time intervals between packets, semantic information of IP addresses and port numbers (0113-0115, 0037).
With regard to claim 10, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the second feature vector includes, for the plurality of devices in the network, one or more of: a size of each packet, time intervals between packets, semantic information of IP addresses and port numbers (0113-0115, 0037).
With regard to claim 11, Howlett in view of Lei in further view of Dean discloses the method of claim 1, as outlined above, and Howlett further discloses the remediation action includes one or more of: factory resetting the first device, rebooting the first device, transmitting an alert about the anomalous behavior of the first device to a network administrator of the network, limiting the access to the network by the first device, blocking/re-directing traffic of the first device, and removing the first device from the network (0053, 0147).
Response to Arguments
Applicant's arguments filed 10 March 2026 have been fully considered but they are not fully persuasive. The amendment overcame the prior rejection, but a new rejection was made, as outlined above.
References Cited
Oleson et al., USPN 2021/0350180, discloses a method for analyzing device data within a network using trained machine learning models (0022), similar to that of Howlett, Lei, and Dean, and further discloses each anomaly model is corresponding to and trained using only traffic of a respective different device from the plurality of devices (0072).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JACOB LIPMAN whose telephone number is (571)272-3837. The examiner can normally be reached 5:30AM-6:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JACOB LIPMAN/Primary Examiner, Art Unit 2434